> Markdown version of [/jobs/ext/1935574-senior-cloud-security-engineer-aws-rmf-ato](https://www.wearedevelopers.com/jobs/ext/1935574-senior-cloud-security-engineer-aws-rmf-ato). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cloud Security Engineer (AWS / RMF / ATO) - **Company:** AURIA, LLC - **Location:** Colorado Springs, CO, United States (Remote available) - **Experience:** Expert - **Salary:** $130,000.0 - $170,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Systems Engineering, Cloud Computing Security, Cyber Security, Computer Engineering, Continuous Integration, Network Security, Cloud Services, Zero Trust Network Access, Security Information and Event Management, Data Logging, Information Security Management System, Containerization, Kubernetes, Information Technology, Nessus, Marketplace, Scap Compliance Checker, Devsecops, Serverless Computing, Docker, Plan of Action and Milestones, Vulnerability Analysis, Microservices - **Published:** August 5, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9075009/senior-cloud-security-engineer-aws-rmf-ato ## About the Role * Bachelor's degree Cybersecurity, Computer Engineering, Computer Science, or related field preferred; equivalent experience considered. * U.S. Citizenship with ability to obtain and maintain a DoD TS/SCI clearance. * 5 years of experience in cybersecurity engineering for DoD, NASA, NOAA or mission-critical systems * At least 2 years' hands-on experience securing AWS cloud environments. * Demonstrated experience supporting DoD RMF accreditation and ATO processes * Strong knowledge of: + NIST SP 800-53 security controls + DoD STIG implementation + FedRAMP security requirements + DoDI 8510.01 RMF process * Experience with vulnerability scanning tools such as ACAS or Nessus * Mission-Driven Professional: Collaborative contributor motivated by the opportunity to develop cutting-edge solutions that protect and serve both the nation and the world. WHAT THE TEAM PREFERS: * Active DoD Secret or TS/SCI clearance * Experience with AWS GovCloud or IL4/IL5 environments * Familiarity with containerized environments (Docker, Kubernetes) and their security implications. * Experience with SIEM platforms, endpoint protection, or security monitoring tools * Knowledge of Zero Trust Architecture principles * DoD 8570 / 8140 certification such as: + Security+ + CISSP + CASP+ + CySA+ ## Description Auria is seeking a Senior Cloud Security Engineer to support the security architecture and accreditation of AWS cloud-hosted mission systems supporting the DoD USSF Joint Antenna Marketplace (JAM) program. This role focuses on implementing and securing AWS cloud environments and executing Risk Management Framework (RMF) activities to obtain and maintain an Authority to Operate (ATO). This position is remote with preference for Colorado Springs, CO or Huntsville, AL. The successful candidate will work closely with program chief engineer, cybersecurity lead, system engineers, and software developers to ensure secure cloud architecture, actively support deployment of security tools and services, and compliance with DoD cybersecurity standards. WHAT YOU CAN EXPECT TO DO: System & Cloud Security Implementation: * Identify and evaluate cloud-based COTS/GOTS/AWS-native infrastructure components to support and deploy security compliance tooling. * Collaborate with systems engineers and software developers to implement security-by-design principles * Integrate security controls into CI/CD pipelines, containerized applications, and microservice architectures. * Implement and maintain secure AWS cloud environments supporting DoD mission systems * Apply secure cloud architecture patterns and AWS security services to support compliance with DoD security requirements. * Implement security controls aligned with NIST 800-53, FedRAMP, and DoD security guidance. * Integrate security controls into DevSecOps pipelines and cloud-native services. * Configure and manage identity, encryption, logging, and network security withing AWS environments. RMF & ATO Support * Execute Risk Management Framework (RMF) activities in accordance within eMASS IAW DoDI 8510.1 and DoDI 8500.01. * Develop and maintain RMF artifacts including: + System Security Plan (SSP) + Plan of Action and Milestones (POA&M) + Risk Assessment Reports (RAR) + Security Control Traceability Matrix (SCTM) * Maintain cybersecurity documentation and evidence within eMASS * Support preparation of ATO packages and security authorization activities * Coordinate with program ISSMs, cybersecurity lead, government stakeholder to support system accreditation. Vulnerability & Compliance Management * Perform vulnerability scanning and remediation using tools such as ACAS, Nessus, OpenSCAP, or SCAP Compliance Checker * Implement and validate DISA STIGs and security baselines across operating systems, containers, and cloud services. * Support continuous monitoring activities required to maintain system accreditation. * Integrate security controls into CI/CD pipelines, containerized applications, and microservice architectures. Documentation & Program Support * Produce cybersecurity documentation and technical artifacts supporting RMF accreditation * Participate in technical interchange meetings, system design reviews, integration events, and program management review. * Support cybersecurity testing, demonstrations, and operational deployments. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Get security done: streamlining application security with Aikido](https://www.wearedevelopers.com/videos/1638-get-security-done-streamlining-application-security-with-aikido) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)